|
210691
|
7.5 |
HIGH
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21996
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210692
|
9.8 |
CRITICAL
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xm…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-21994
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210693
|
6.1 |
MEDIUM
Network
|
wems
|
enterprise_manager
|
In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21993
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210694
|
9.8 |
CRITICAL
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the auto…
|
CWE-287
Improper Authentication
|
CVE-2020-21991
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210695
|
6.1 |
MEDIUM
Network
|
homeautomation_project
|
homeautomation
|
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an …
|
CWE-601
Open Redirect
|
CVE-2020-21998
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210696
|
8.8 |
HIGH
Network
|
homeautomation_project
|
homeautomation
|
HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to ve…
|
CWE-352
Origin Validation Error
|
CVE-2020-21989
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210697
|
6.1 |
MEDIUM
Network
|
homeautomation_project
|
homeautomation
|
HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21987
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210698
|
4.8 |
MEDIUM
Network
|
x2engine
|
x2crm
|
Cross Site Scripting (XSS) in X2engine X2CRM v7.1 and older allows remote attackers to obtain sensitive information by injecting arbitrary web script or HTML via the "First Name" and "Last Name" fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21088
|
2024-11-21 14:12 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210699
|
6.1 |
MEDIUM
Network
|
x2engine
|
x2crm
|
Cross Site Scripting (XSS) in X2Engine X2CRM v6.9 and older allows remote attackers to execute arbitrary code by injecting arbitrary web script or HTML via the "New Name" field of the "Rename a Modul…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21087
|
2024-11-21 14:12 |
2021-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210700
|
8.8 |
HIGH
Network
|
indionetworks
|
unibox_u50_firmware unibox_u500_firmware unibox_u1000_firmware unibox_u2500_firmware unibox_u5000_firmware
|
Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduse…
|
CWE-352
Origin Validation Error
|
CVE-2020-21884
|
2024-11-21 14:12 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|